AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company aggregates Amazon GuardDuty findings in AWS Security Hub for 12 AWS accounts. During quarterly penetration tests, thousands of Recon:EC2/PortProbeUnprotectedPort findings are generated. The security team wants these specific findings to be automatically marked as suppressed so they disappear from the default Security Hub dashboard, yet remain stored and searchable for audit investigations. Which approach meets the requirement with the least operational overhead?
Define a Security Hub custom action that sets the Workflow status to SUPPRESSED and instruct penetration testers to run the action after each test.
Configure an Amazon EventBridge rule to invoke an AWS Lambda function that deletes matching findings from Security Hub.
Create a Security Hub automation rule that filters on the Recon:EC2/PortProbeUnprotectedPort finding type and sets the finding's Workflow status to SUPPRESSED.
Build a Security Hub insight for the finding type and rely on the insight to hide the findings from the default dashboard.
Security Hub automation rules can evaluate every new or updated finding against filter criteria and then apply updates such as changing the Workflow status to SUPPRESSED. When a finding is suppressed, it is removed from the default view but is still retained in Security Hub and can be queried later, satisfying the audit requirement. Insights only group findings for reporting and do not change their workflow status. A CloudWatch Events (EventBridge) rule that deletes findings is not possible because Security Hub does not support deleting findings; such a Lambda solution would also add unnecessary complexity. Custom actions must be invoked manually or called explicitly through the API, so they do not provide the fully automatic behavior requested.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Amazon GuardDuty finding, and how is it used in AWS Security Hub?
Open an interactive chat with Bash
What is the Workflow status in AWS Security Hub findings, and what does 'SUPPRESSED' mean?
Open an interactive chat with Bash
How do Security Hub automation rules work, and why are they efficient for managing findings?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .